Skip to content
Nonprofit Solutions AIMission-first AI field lab

Nonprofit AI field guide

Reviewed July 21, 2026

Map data before choosing a tool

Understand what would enter, leave, persist, or influence the workflow before comparing features.

01

Follow the information through the work

List the source, fields, people represented, sensitivity, owner, approved purpose, destination, retention, and deletion path for every piece of information the use case might touch.

Include prompts, attachments, copied text, generated output, logs, feedback, integrations, exports, and account metadata. The visible chat box is only one part of the data path.

02

Reduce before you upload

Ask whether the test can use fictional, public, de-identified, aggregated, or minimum necessary information. Remove names, free-text notes, identifiers, secrets, credentials, and protected records unless an accountable owner has approved a controlled path.

Do not treat de-identification as a magic label. Small populations, unusual facts, linked fields, and external datasets can make people recognizable again. Use qualified privacy and security review when the information or consequence is sensitive.

03

Verify the service boundary

Review the provider's current terms, privacy commitments, training settings, retention, administrative controls, region, subprocessors, export options, and incident process for the exact plan and account type under consideration.

Record what was verified, by whom, from which official source, and on what date. Product behavior and contractual terms change. A safe conclusion needs an owner and a review date.

Monthly field note

Get practical guidance in your inbox.

Monthly field guidance for mission fit, data boundaries, human review, and bounded AI pilots.
Required